PkgRadar

npm · registry.npmjs.org

muaddib-scanner

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 2.11.78

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · package/src/scanner/ast-detectors/constants.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/src/scanner/deobfuscate.js
highWebhook Exfil Endpointmatched "canarytokens.org" · package/src/rules/index.js
highWebhook Exfil Endpointmatched "discord.com/api/webhooks/" · package/src/sandbox/index.js
highWebhook Exfil Endpointmatched "webhook.site" · package/src/sandbox/network-allowlist.js
highWebhook Exfil Endpointmatched "webhook.site" · package/src/response/playbooks.js
highDNS / OAST exfiltrationmatched "oastify.com" · package/src/scanner/ast-detectors/constants.js
highDNS / OAST exfiltrationmatched "oastify.com" · package/src/rules/index.js
highDNS / OAST exfiltrationmatched "oastify.com" · package/src/sandbox/network-allowlist.js
highDNS / OAST exfiltrationmatched "oast.fun" · package/src/scanner/package.js
highDNS / OAST exfiltrationmatched "oastify.com" · package/src/response/playbooks.js
mediumCredential file accessmatched ".npmrc" · package/src/scanner/package.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.11.78High risk1962026-06-08
2.11.77High risk1962026-06-08

Related campaigns

Block this in CI

PkgRadar gates muaddib-scanner (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]